CVE-2026-33711
published 2026-03-26CVE-2026-33711: Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.6th percentile
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`. On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering the mode and permissions of arbitrary files on the filesystem, leading to a potential denial of service or possible local privilege escalation. Version 6.23.0 fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | incus | < incus 6.0.6-2 (forky) | incus 6.0.6-2 (forky) |
| github.com | lxc_incus_v6 | >= 0 < 6.23.0 | 6.23.0 |
| linuxcontainers | incus | < 6.23.0 | 6.23.0 |
| lxc | incus | < 6.23.0 | 6.23.0 |
| lxc | incus | >= 0 < 6.0.6-2 | 6.0.6-2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.04.7MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incus vulnerable to local privilege escalation through VM screenshot path in github.com/lxc/incus
osv·2026-04-07
CVE-2026-33711 Incus vulnerable to local privilege escalation through VM screenshot path in github.com/lxc/incus
Incus vulnerable to local privilege escalation through VM screenshot path in github.com/lxc/incus
Incus vulnerable to local privilege escalation through VM screenshot path in github.com/lxc/incus
OSV
Incus vulnerable to local privilege escalation through VM screenshot path
osv·2026-03-27
CVE-2026-33711 [MEDIUM] Incus vulnerable to local privilege escalation through VM screenshot path
Incus vulnerable to local privilege escalation through VM screenshot path
### Summary
Incus provides an API to retrieve VM screenshots, that API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion.
As Incus uses predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time.
On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`.
On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering th
GHSA
Incus vulnerable to local privilege escalation through VM screenshot path
ghsa·2026-03-27
CVE-2026-33711 [MEDIUM] CWE-61 Incus vulnerable to local privilege escalation through VM screenshot path
Incus vulnerable to local privilege escalation through VM screenshot path
### Summary
Incus provides an API to retrieve VM screenshots, that API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion.
As Incus uses predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time.
On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`.
On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering th
OSV
CVE-2026-33711: Incus is a system container and virtual machine manager
osv·2026-03-26·CVSS 4.7
CVE-2026-33711 [MEDIUM] CVE-2026-33711: Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`. On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering the mode and perm
Red Hat
incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths
vendor_redhat·2026-03-26·CVSS 4.7
CVE-2026-33711 [MEDIUM] CWE-59 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths
incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`. On the rare systems with this purp
Debian
CVE-2026-33711: incus - Incus is a system container and virtual machine manager. Incus provides an API t...
vendor_debian·2026·CVSS 4.7
CVE-2026-33711 [MEDIUM] CVE-2026-33711: incus - Incus is a system container and virtual machine manager. Incus provides an API t...
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`. On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering the mode and perm
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33711 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.7
CVE-2026-33711 [MEDIUM] CVE-2026-33711 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33711 :
Homebrew vulnerability analysis and mitigation
protected_symlinks
Source : NVD
## 4.7
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Homebrew
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
incus
github.com/lxc/incus/v6
Sources
NVD
Debian 13 Severity LOW No Fix Added at: Mar 29, 2026
Debian 14 Severity LOW Has Fix Added at: Mar 29, 2026
Echo Severity HIGH No Fix Added at: Mar 29, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 29, 2026
Homebrew Severity HIGH Has Fix Added at: Apr 02, 2026
## Get a CVE risk assessment
Get a prior
Bugzilla
CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-42]
bugzilla·2026-03-26·CVSS 4.7
CVE-2026-33711 [MEDIUM] CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-42]
CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-a9017d0297 (incus-6.23-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a9017d0297
---
FEDORA-2026-a9017d0297 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a9017d0297`
You can provide feedback for this updat
Bugzilla
CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43]
bugzilla·2026-03-26·CVSS 4.7
CVE-2026-33711 [MEDIUM] CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43]
CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-5af38b7ecb (incus-6.23-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5af38b7ecb
---
FEDORA-2026-5af38b7ecb has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-5af38b7ecb`
You can provide feedback for this updat
2026-03-26
Published